6 Repos
Repositories of detection logic, signatures, and analytic queries.
Explore 6 awesome GitHub repositories matching part of an awesome list · Detection Rules and Analytics. Refine with filters or upvote what's useful.
Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that
Generic signature format for SIEM systems.
ThreatHunter-Playbook ist ein Framework für Threat-Hunting-Playbooks und ein Detection-Engineering-Workflow, das darauf ausgelegt ist, den Sicherheitserkennungs-Lebenszyklus zu standardisieren. Es fungiert als Community-getriebenes Repository für Angreifer-Methoden und Erkennungslogik und nutzt interaktive Notebooks, um technische Dokumentation mit ausführbaren Analysen zu kombinieren. Das Projekt bietet eine Validierungssuite zum Testen von Sicherheitshypothesen gegen vorab aufgezeichnete Telemetrie-Datensätze. Dies stellt sicher, dass die Erkennungslogik in lokalen oder Cloud-Umgebungen verifiziert wird, bevor sie in der Produktion eingesetzt wird. Das Framework deckt Sicherheits-Detection-Engineering, Threat-Hunting-Standardisierung und die Formalisierung der Hunt-Planung ab. Es nutzt strukturierte Vorlagen und komponentenbasierte Modellierung, um den Prozess von der ersten Hypothese bis zur endgültigen Validierung zu leiten.
Community project for sharing detection logic and tradecraft.
This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base
Collection of detection rules for security monitoring.
This repository contains example YARA-L rules and dashboards for use within Google Security Operations (SecOps)
YARA-L rules for cloud-based detection APIs.
Community-driven audit and threat queries for cloud environments.
Detection and response rules for email threats.